[OAUTH-WG] OAuth 2.0 Protected Resource Metadata now with WWW-Authenticate

Michael Jones <michael_b_jones@hotmail.com> Tue, 11 July 2023 00:34 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6CDF7C17CE99 for <oauth@ietfa.amsl.com>; Mon, 10 Jul 2023 17:34:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.221
X-Spam-Level:
X-Spam-Status: No, score=-1.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GncsTna42ZlH for <oauth@ietfa.amsl.com>; Mon, 10 Jul 2023 17:34:31 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11olkn2077.outbound.protection.outlook.com [40.92.19.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9DE1BC17D667 for <oauth@ietf.org>; Mon, 10 Jul 2023 17:34:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Efy+79JeQmhooNjZK485IBBZFjGAAf5jQh4nwtX3kuS5SmZ/Kv/ZsnP8RhZek0gAseAVPZoOiopozkV9NNeyt5fIWKb02BFlxxO5PPVDBw4ho8eruGoomBgvZZTcW1NSlh56x4/7EQhmivtgbB1j+eYvdN/eY5usAbkOmFuysDTji4eXuK8WOBLbzFNX6iiXmVz+gh/rLDSEir1E8KijsxvIj93hc29sWT5rWph9xQJ1WZAuJ0M+/RU/FohEkBjnU055O60/L1cHbNLTuKanrNq+Z1UmPd8QHXi2hqcqq90Vx2Cg1jv/AGfFinPH9zGqROao2nKaNhZhhR3ONxtxAQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+A+xZC689F+XAl+8p3zLfewR5IjFKU9yuxNBQwcLW9A=; b=VAWeQRU+Xmp/fs4e1p4AsDBjblgan54pjF1iv/OQ4Lq+1SqTc6FkpAhloxTHqiXk2OtnUtQEUIBqkWsFUyo39tKATOw5fyM/B4kMR32EtDMIQgf9nTDNH/zptCwfqGVPRoyL98pK1LVgSYD4iOK4TCHUvbSQiTY6n5g3D0yFsnJOlfFETvgkGdwvTojXTDkLaS+2x5f1f6QZ8lQQOTiF8aOUqasDNdNLYLB0z4ljgOxA1/7NAAV5GQZvnH1FHDmJzzo8t188EekmHNAFRLgmDbg88vtMBixVa/9JIWS9tjn3nTZFxOq0PMnQf6L3yssjx6LNQ/wuKUtulHZ0J5CYMA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+A+xZC689F+XAl+8p3zLfewR5IjFKU9yuxNBQwcLW9A=; b=D0c20YYQfo37SVGIPdZ/YMGyGDX1KYjw41WCnQrIN30OIKPowIL2vxyR+JPUkmFwd1cxaGCkCdXOoa82qBgjGh2oQEXVY4XO2vPfS+xMh/N/AN9YmCcxzUCO8fmN9AzAyY0pLTFHYuuHOPshS9W3M4IUeDAbXxaEZjg6BQZ2fCGo/7cInGxBtEeVRFldJYQiKPpPqj2YpR0eIlYB7lAuaDWMIP3wxJXHrUPaRmjmJO957lHWNLYkxtHsST+86RkVI8GCggkKnN8YNKfKNKJzTj+e2bo1Bm7X4xczypZ2nZY1myq1IAasMiWs72PowtA3bPH5UA3+xPV6szt6NqF3nw==
Received: from MW4PR02MB7428.namprd02.prod.outlook.com (2603:10b6:303:71::5) by DM6PR02MB6713.namprd02.prod.outlook.com (2603:10b6:5:21b::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6588.19; Tue, 11 Jul 2023 00:34:30 +0000
Received: from MW4PR02MB7428.namprd02.prod.outlook.com ([fe80::e7bf:b257:d77f:97e9]) by MW4PR02MB7428.namprd02.prod.outlook.com ([fe80::e7bf:b257:d77f:97e9%2]) with mapi id 15.20.6588.013; Tue, 11 Jul 2023 00:34:30 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: OAuth 2.0 Protected Resource Metadata now with WWW-Authenticate
Thread-Index: AdmzjvHSMw8vqEzERwqO2iMnYg7MaQ==
Date: Tue, 11 Jul 2023 00:34:30 +0000
Message-ID: <MW4PR02MB742844C56F175D4E359EDD07B731A@MW4PR02MB7428.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [/Nbuy4M3IEk10ZTI5aTeToEafjRcQPJ706vOEjuwmtYeJjVA8pwMcqsJIfnHfjzFdmpLaqLZa1s=]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MW4PR02MB7428:EE_|DM6PR02MB6713:EE_
x-ms-office365-filtering-correlation-id: e0c1f02d-e2af-4c23-9b54-08db81a69719
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: gJbvde5dpUhQVgQ6ErAm9LREVIutUcsFJPIDtuUzQcfL91++4lq71kqvWwsp5/gEuDkf0IK41l00wrYi0cPB5suLx6YkMgPf2bILENKp8DK7R9o82hhFjDu+7kZw5inS/FAWMqRUJQsZfuuXEfgQOceol5Vf7xzcwry9LccCh9wMq8ctE6mLQzKdKTMneSGRYQ/2mr/TPWbe8nPmhnCX5I4dmlNar9K/tILnkRoI4H0kkXrgP0mWUDWcFJ0tNScpIHtbtQeEH49JeguvxeUJWn5PhJFiIRp4KnpLPKB27xc3vSqldfs5dKv8egmCAf+DRtc31+H4lmf2F8UX/Dr7qBZFUE0iP95XV2gnq32fKp8fHvVq7wqNVaL1LqPr6DkfPAIgtR0Kv0UAaKmw14LVlEj2x+R5ivfhh7IQze49YmXPLqqR2xcMfIKVrMMByMfWy5AsOI4K9QHf+qpy3bfeXWqFjNHPu20zA7zMj1xlNZ8kTRYunXH0U/0vCCPH4hybujOAjs9sXp3mmxB6kj4J7jGDytUJ2Y1XtLtEKENJ/9Lbzu8iB5oSd1k8M6BP6QyxdA9b12bRmNXEg5rWu/2oGI/jvZTLR0bS8dsU+BIDeBdzYzdVTlRBM6qqCVq4e7al76CSlSkhwCdmKqiCjf4q4g==
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Qkx5lA7O8MPNZcUd3FZjNnpoqS2EwJopL9brrenUVh8T15ZsWYXyOIlqiUWjnJ2ahM/quHeGtFZpCQGPAyZVIUofXDiaeuEE3EcGzfe9WftClzwDYiuLCrtWI4WeGuFL1V+UvHRH7ehOORcfKgPtX+t+lWWeQp0bnseZlgcxg3dPuFQGhPx/ml8CB/yjzjm55TO+N2IjhpI3Ia2GZeUX2pbD1FFxiqp8+wFZp9rQJQYHyIeMsIsfYy9U27at5I+BVQoKKmxOzadQKNSYpUhOz+BGSxQkyoIv0wSUA5NMkAYPRoGZe1ZzYzR1UimEXzCO7PTBHvWsuR7ry2D3pX8kku3ae28ltMHQKUf7Z/hgz8HQKdJzjQfGCFsE7rzGy/hYj6bN0eR6qD0bcu9VLDQwT0yy3mWjz7xYZbbxlvQcVT28Kprf+hFb416ctEA4O4IWtsp+JjES7DzvrxEy3ekogtrvBiDDVQNfrU43HswkQHZWQ9Tq1SdngLDtu9HXyZEn88Jg437kBKMY2s8gEL0yZFR+SY4jvU+fkw//3REFWvzA4uFtaTAFd5QxBslxSOQgJzk1ZQoUZ3m7rldqpcyUtAiRPhZ1zymwTY8DSvLxiwPjI2PPnFby8Hf21ol5FBcqyADZDh/GIP8zhtlW5R+bHsd0QfpC2cpMAJwyMALQ/9N4+hxH2LPSgNRN5vG5eeKIoGA6PzX00zVPurDZXDtxcgZar3L72DveSOMs4D6bU02YfG6xMC9l5xfOoSpewmLM+9BrPDUq8nNsV/X5M3Y6fTEtEyYRakUyJ/ZI6RXF7uxaQqCJUiHxnsOOvU7rpVHYoaiVASbt8aV85RYhA+LsbV0ypjKweUNzkOWn6BpIYDz9/LJmlKd0CVCCxQn2/ED/9J0KNkM0YY4SlQIoPUvr2IHtzSfiV/fybwtdnIOPKFyFnxChYYjZBrm0kIIx2QkMDWOJApIgskVhAmbzbFcpsWgj6n1BVqcWAbnelajPeQK9tBu0YJxojvjY/HjSCBMrL3VVBt6R8j1vw/9O+7hJ9+ldAbAT4ykYkVu6dOe88yhttXGBm737Exg04z77WW6WcjHTNKn9V/CWracJDx8+e5MEZarmhP20QAqCk68fGGMXW8WXdlClVKlHL6ZH1NYlN5hddmoNZoejFRTfWjZ2e/sS9N2IvXWoIzG2Bwp0om8SlH5c50WUiP0u8tTjQfr54jhBq2EjSNOdi9E3dHCx3bWvGZNQq9xctwGrjKlnzIA6oYwMluECJrBL3Pnb6M09mRqkDOPI5uf50v+QUByGMzoWnHVa239LtgAYbUYktzU=
Content-Type: multipart/alternative; boundary="_000_MW4PR02MB742844C56F175D4E359EDD07B731AMW4PR02MB7428namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-99c3d.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MW4PR02MB7428.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: e0c1f02d-e2af-4c23-9b54-08db81a69719
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Jul 2023 00:34:30.2614 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR02MB6713
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/5RQSZ9doUVeuuUQ_RDuCACq9v7w>
Subject: [OAUTH-WG] OAuth 2.0 Protected Resource Metadata now with WWW-Authenticate
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Jul 2023 00:34:35 -0000

In collaboration with Aaron Parecki<https://twitter.com/aaronpk>, the ability for OAuth 2.0 protected resource servers to return their resource identifiers via WWW-Authenticate has been added to the OAuth 2.0 Protected Resource Metadata specification. This enables clients to dynamically learn about and use protected resources they may have no prior knowledge of, including learning what authorization servers can be used with them.



This incorporates functionality originally incubated in draft-parecki-oauth-authorization-server-discovery-00<https://www.ietf.org/archive/id/draft-parecki-oauth-authorization-server-discovery-00.html>. Aaron and I had been asked to merge the functionality of our two drafts during an OAuth working group session at IETF 116. We're both happy with the result!



The specification is available at:
*        https://www.ietf.org/archive/id/draft-jones-oauth-resource-metadata-04.html

                                                       -- Mike

P.S.  This notice was also posted at https://self-issued.info/?p=2377 and was referenced from https://twitter.com/selfissued/status/1677471513023508481.